Courselob Wersja polska

Privacy policy

Information on the processing of personal data Version 1.0 In force from the launch of the Service

This is a courtesy translation. The binding version is the Polish one. This English text is provided so that you can understand how your data is handled — it has no independent legal effect, and where the versions differ, the Polish version prevails.

This document says what data Courselob collects, why, on what legal basis, who receives it and how long it is kept. The Service runs no analytics, has no tracking pixels and no marketing cookies — which is why you will not see a cookie consent banner here.

Who the controller is

  1. The controller of your personal data is Piotr Zacharek, conducting sole-trader business activity under the name PIOTR ZACHAREK, registered office in Poznań, Poland, NIP 7821005108, REGON 631505817. Full address is given in § 1(1) of the Polish version.
  2. Contact on data matters: support@courselob.com.
  3. No data protection officer has been appointed — there is no obligation to do so. Write to the address above on all matters.

What data we collect

  1. When creating an account: email address and password (stored only as an irreversible hash — we do not know your password and cannot read it).
  2. When signing in with Google: email address and account identifier passed on by Google. We do not read contacts, files or history.
  3. When using the service: the course topic you type, the generated materials, the chosen language and course settings, Token usage and the chosen plan.
  4. When you contact us: the message, the email address and the time it was sent. This applies both to the contact form and to the chat in the panel.
  5. When paying: we neither collect nor see your card details. Stripe handles them (§ 5). We receive only the payment confirmation, its amount and status.
  6. Technical data: IP address and browser information, recorded in server logs for security purposes.
  7. We do not collect special categories of data (health, beliefs, religion and the like) and we ask that you do not put such information into the topics you type or into messages to us.

Why, and on what legal basis

Legal bases come from Article 6 of the GDPR — Regulation (EU) 2016/679.

PurposeDataLegal basis
Creating and running an accountemail, password, Google identifierArt. 6(1)(b) — performance of a contract
Generating course materialstopic, settings, generated contentArt. 6(1)(b) — performance of a contract
Settling payments and plansemail, plan, payment statusArt. 6(1)(b) — performance of a contract
Issuing and keeping accounting documentsbilling dataArt. 6(1)(c) — legal obligation
Handling complaints and withdrawalscorrespondence, account dataArt. 6(1)(c) — legal obligation
Answering messages and support chatemail, message contentArt. 6(1)(f) — legitimate interest: replying to someone who wrote to us
Security, preventing abuseIP address, server logsArt. 6(1)(f) — legitimate interest: protecting the Service and its users
Establishing and pursuing claims, or defending against themaccount data, correspondence, billingArt. 6(1)(f) — legitimate interest

We send no newsletter and no marketing messages. If we ever start, we will ask for separate consent first, revocable with one click.

How long we keep it

DataPeriod
Account and generated materialswhile the account exists; after deletion — up to 30 days to undo an accidental deletion, then permanently erased
Accounting documents5 years from the end of the tax year in which the tax obligation arose — required by law
Correspondence and support chatup to 2 years from the last message
Data needed for claimsuntil the limitation period expires, usually 6 years
Server logsup to 12 months

Who receives it

  1. We use companies that process data on our behalf under data processing agreements. The list below is complete — we pass data to nobody outside it.
  2. We do not sell data and do not share it for marketing purposes with anyone.
WhoWhat forWhat data
Supabasedatabase, sign-in, file storage — servers in the European Unionemail, password hash, materials, correspondence
Vercelhosting the site and server functions — functions run in Frankfurttechnical data, request content
Telegram notifying the support team that a new message arrived — servers outside the European Economic Area your email address and the content of your message
Stripepayment handlingemail, amount, card details — processed by Stripe only
Anthropicthe model that writes course content and answers in the help chatcourse topic and generation parameters; the question you type in the chat
Resendsending email (purchase confirmations, password recovery)recipient email address and message content
ntfy.shnotifying the team about a new message from a usersender email address and message content
Google (search)fetching the search results shown inside a lesson videothe search phrase
Pexelsphoto search for lessons and the course pagea search phrase built from the course topic; when photos are displayed, also the visitor's IP address and browser details
ElevenLabsvoice synthesisthe text to be read aloud
Googlesign-in with Google — only if you use itemail, account identifier
  1. Data may be disclosed to state authorities where required by law.
  2. Fonts and libraries needed for the site to work are loaded from our own server — no content delivery networks, tracking pixels or third-party scripts. One exception: the photos illustrating courses load directly from Pexels servers, so displaying them sends your IP address and browser details to that provider. Otherwise your IP address does not reach anyone beyond the table above.

Transfers outside Europe

  1. Your account, courses and correspondence are stored on servers in the European Union. The Service's server functions run in Frankfurt.
  2. Only data strictly needed for a specific operation is transferred outside the European Economic Area, to the United States:
    1. Pexels — a photo search phrase built from the course topic, when the page picks images;
    2. Resend — your email address and the message content, when we send you a confirmation or a password-reset link;
    3. ntfy.sh — your email address and message content, when you write to the team (a notification for us);
    4. Anthropic — the course topic and generation parameters, when you ask for materials to be generated;
    5. ElevenLabs — the text to be read aloud, when you use the narrator;
    6. Google — email address and account identifier, only if you sign in with Google;
    7. Stripe — payment data, processed by Stripe Payments Europe based in Ireland, with possible support from affiliates outside the EEA.
  3. Separately, outside the EEA to the United Arab Emirates, we transfer your email address and the content of the message you send us — to Telegram FZ-LLC. The reason is a single one: notifying the support team that you are waiting for an answer. If you prefer your message not to leave Europe, write directly to support@courselob.com — email does not travel this route.
  4. Transfers take place on the basis of standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR) or, for providers in the Data Privacy Framework, on the basis of an adequacy decision (Art. 45 GDPR).
  5. We will provide a copy of the safeguards used on request sent to support@courselob.com.

Your rights

  1. You have the right to:
    1. access your data and receive a copy;
    2. rectify data that is incorrect or incomplete;
    3. erasure (“the right to be forgotten”);
    4. restriction of processing;
    5. data portability — receiving it in a machine-readable format or having it sent to another controller;
    6. object to processing based on legitimate interest (Art. 6(1)(f)).
  2. Send your request to support@courselob.com from the address linked to your account. We answer without delay and within one month at the latest.
  3. You have the right to lodge a complaint with the supervisory authority — the President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
  4. Exercising these rights is free of charge.

Is providing data obligatory

  1. Providing data is voluntary but necessary to use the service.
  2. Without an email address you cannot create an account or keep the materials you generate.
  3. The topic analysis, title suggestions and section plan can be seen without creating an account — a typed topic is enough.

Automated decisions and profiling

  1. We take no decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you.
  2. The Service uses an artificial intelligence model to create course content from the topic you supply. The model does not assess you and takes no decisions about you — it processes only the content you type yourself.
  3. We do not profile users for advertising.

Browser storage and cookies

  1. The Service uses no analytics or marketing cookies and no tracking tools. That is why there is no cookie consent banner — there is nothing to consent to.
  2. We store in your browser only what the service needs to work:
    1. the chosen site language and course language;
    2. the course you are working on and your Token usage;
    3. the chosen plan;
    4. session data — without it every page change would require signing in again.
  3. This data stays on your device and you can delete it at any time in your browser settings. Deleting session data signs you out.

Security

  1. The connection to the Service is encrypted (HTTPS).
  2. Passwords are stored only as irreversible hashes. We do not know your password and will never ask for it — including when you write to support.
  3. Access to data in the database is limited by rules enforced on the server side: each user sees only their own courses and their own correspondence.
  4. Only people named individually in the database configuration have access to the support panel.
  5. If a personal data breach occurs that may result in a high risk to your rights, we will notify you without undue delay, and the supervisory authority within 72 hours.

Changes to this policy

  1. We may change this policy, in particular where the law, the scope of services or the list of providers in § 5 changes.
  2. Account holders are notified by email at least 14 days before a material change takes effect.
  3. The version and the date it applies from are always given at the top.